Network Device Configuration via Remote Verification Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices require on-site configuration, which is costly and insecure, as they can be remotely altered, compromising security once access is gained.

Innovation Solution

A network device with no initial configuration data that is remotely programmable, using secure encryption to contact a remote verification authority for complete configuration data download, ensuring only authorized changes can be made, and configuration data is lost on power loss or intrusion attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote configuration access is provided to avoid on-site attendance, then configuration cost and time are reduced, but security is compromised as unauthorized changes can be made

Engineering Contradiction:
Improveconfiguration efficiencyVSAvoidconfiguration security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-establishing encrypted communication channels and authentication mechanisms before any configuration changes occur. The verification authority validates device identity and authorization status in advance, ensuring that only authorized configuration changes can be made remotely, thus preventing unauthorized modifications while enabling remote configuration capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A verification authority acts as an intermediary between the configuration device and the network device. This intermediary validates authentication credentials, verifies device identity, and controls the configuration update process. The intermediary ensures that configuration changes are authorized and secure, resolving the contradiction between remote accessibility and security by introducing a trusted third party that mediates all configuration interactions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If on-site configuration is required for security control, then configuration security is improved, but cost and time expenditure increase

Engineering Contradiction:
Improveconfiguration securityVSAvoidconfiguration efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network device performs self-verification and self-protection functions by automatically validating its own authentication credentials through the verification authority and automatically rejecting unauthorized configuration changes. The device can detect intrusion attempts and trigger configuration loss or reset procedures autonomously, eliminating the need for continuous on-site personnel while maintaining security through automated self-service mechanisms

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the verification authority continuously monitors configuration requests, validates device status, and provides real-time authorization decisions. The network device receives feedback regarding authorization status and adjusts its configuration acceptance behavior accordingly. This feedback loop ensures security is maintained while enabling efficient remote configuration operations

Inventive Principle:
Principle #23Feedback

3Stability of the object's composition

If configuration data is stored persistently in the device, then configuration stability is improved, but security risk increases as hackers can extract and modify it

Engineering Contradiction:
Improveconfiguration stabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The system changes the storage parameter of configuration data from persistent storage to volatile memory (RAM). Configuration data is held in random access memory and is lost when power is removed or when intrusion is detected. This parameter change from permanent to temporary storage eliminates the security vulnerability of persistent configuration storage while maintaining configuration stability through controlled reloading from the verification authority

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system prepares protective measures in advance by implementing intrusion detection mechanisms that monitor for hacking attempts before they can extract or modify configuration data. When intrusion is detected, the system proactively triggers configuration data loss or reset procedures, cushioning against potential security breaches. This beforehand cushioning ensures that even if hackers attempt to access persistent storage, the configuration data is already protected through pre-established detection and response mechanisms

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS8171143B2Network device configuration
Publication Date: 2012.05.01 MAKO NETWORKS INC
  • US8171143B2 patent drawing
  • US8171143B2 patent drawing

AI summary

A network device initially has no configuration data and is permitted only to query a known network address. From this address a server verifies the connection and authorizes another server to download to the network device the necessary configuration to carry out its purpose. This configuration may not be amended and is not retained on power loss. Any updates are carried out by a complete reload of configuration data.